Back to skill

Security audit

🎨 Text-to-Image Free

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its copy-paste execution instructions are unsafe because a crafted image prompt can become executable Python code on the user's machine.

Install only if you are comfortable with prompt text being sent to Pollinations.ai, and avoid using sensitive or confidential prompts. The command examples should be fixed before use by passing prompts as data, not embedding them in python3 -c source, and by writing output to a unique private temporary file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:52
Finding

User-Controlled Prompt Embedded in Executable Python Source

Content
View full analysis
" WIDTH=1024 HEIGHT=768 SEED="" # optional: "42" curl -s --max-time 180 \ "https://image.pollinations.ai/prompt/$(python3 -c "import urllib.parse; print(urllib.parse.quote('$PROMPT'))")?width=$WIDTH&height=$HEIGHT&nologo=true${SEED:+&seed=$SEED}" \ -o /tmp/generated_image.jpg ``` ### Technical Analysis The image prompt originates from user input and is interpolated directly into Python source code passed to `python3 -c`: ```python urllib.parse.quote('$PROMPT') ``` Although the prompt is held in a shell variable, its value is expanded inside the Python program. A single quote in the prompt can terminate the Python string literal. An attacker can then append Python statements and comment out the remaining source. This is a code-injection vulnerability rather than ordinary URL manipulation. Shell quoting does not make the operation safe because the expanded value is treated as part of Python source code. A malicious prompt can follow a structure conceptually similar to: ```text '); __import__('os').system(''); # ``` The exact payload may require adjustment for the surrounding expression, but the vulnerable boundary permits attacker-controlled Python statements. ### Attack Path 1. An attacker asks the Agent to generate an image using a prompt containing a single quote and injected Python syntax. 2. The Agent extracts the entire attacker-controlled description into `PROMPT`. 3. The shell expands `$PROMPT` inside the argument supplied to `python3 -c`. 4. The injected single quote closes the intended Python string. 5. The remaining attacker-controlled text is interpreted as Python code. 6. Python executes an operating-system command through funct ...[truncated 1002 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:60
Finding

Predictable Output File in Shared Temporary Directory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes free image generation but does not clearly warn users that their prompts are transmitted to Pollinations.ai, a third-party service. Users may include sensitive, personal, proprietary, or regulated information in prompts, so the lack of an explicit disclosure creates a meaningful privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The English trigger phrases are broad enough to match ordinary conversational requests such as 'draw' or 'make a picture,' which can cause the skill to activate when the user did not intend to invoke an external image-generation workflow. In this skill, unintended activation also sends user-supplied text to a third-party API and performs a network request, making the ambiguity materially security- and privacy-relevant rather than just a UX issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Chinese version likewise omits an explicit notice that user-entered prompts are sent to an external third-party API. This increases the chance that Chinese-speaking users unknowingly disclose sensitive data, especially since the workflow appears seamless and 'free' without surfacing the privacy boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Chinese trigger keywords are similarly overbroad, with common verbs like '画' and '生成图片' that may appear in normal conversation or requests not meant to invoke this skill. Because activation leads to exfiltration of prompt content to Pollinations.ai and execution of a curl request, accidental matching can expose user content and trigger unwanted external actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.